Database/Container, Kubernetes & orchestration
Envoy: URI fragment treated as part of the path
CVSS 8.6CVE-2021-32779Container, Kubernetes & orchestrationcurated
Impact
URI fragment treated as part of the path; authorization bypass
Who can reach it
Unauthenticated network
What to do
Upgrade Envoy
References
Related entries
- Envoy: Processing continues after a local reply, causing undefined behaviourCVE-2021-32781 · EnvoyHigh
- Envoy: Malicious client constructs permanently valid credentials in the OAuth filterCVE-2023-35941 · EnvoyHigh
- Envoy: JWT with an issuer absent from the provider list bypasses JWT authenticationCVE-2021-21378 · EnvoyHigh
- Envoy: Client can forge the x-envoy-original-path header and bypass JWT checksCVE-2023-27487 · EnvoyHigh
- Envoy: Mixed-case HTTP/2 schemes defeat case-sensitive internal scheme checksCVE-2023-35944 · EnvoyHigh
- Envoy: Escaped slash sequences %2F and %5C not decodedCVE-2021-29492 · EnvoyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.